CMS MADE SIMPLE FORGE

CMS Made Simple Core

 

[#12861] doc/htaccess.txt recommended security

avatar
Created By: Philippe Thomas (filto)
Date Submitted: 2026-09-25 22:05

Assigned To: Fernando Morgado (JoMorg)
Resolution: None
State: Open
Summary:
doc/htaccess.txt recommended security
Detailed Description:
in doc/htaccess.txt
----------------------------
# The following are highly recommended security settings for files in your CMSMS
install that should not be browsed directly.
#
RedirectMatch 403 ^/.*\.htaccess$
RedirectMatch 403 ^/.*\.log$
RedirectMatch 403 ^/.*\.ini$
RedirectMatch 403 ^/.*config\.php$
RedirectMatch 403 ^.*/doc/.*$
RedirectMatch 403 ^.*/lib/.*\.php$
RedirectMatch 403 ^.*/tmp/.*\.php$
RedirectMatch 403 ^.*/modules/.*\.php$
RedirectMatch 403 ^.*/uploads/.*\.php$
RedirectMatch 403 ^.*/assets/.*\.php$
RedirectMatch 403 ^.*/assets/.*\.tpl$
--------------------------------

can slow down server if an attacker sends several extremely long URLs


option 1 : avoid or reduce .* (catastrophic backtracking)
--------------------------------
RedirectMatch 403 \.htaccess$
RedirectMatch 403 (?i)\.log$
RedirectMatch 403 (?i)\.ini$
RedirectMatch 403 (?i)config\.php$
RedirectMatch 403 /doc/
RedirectMatch 403 (?i)/lib/.*\.php$
RedirectMatch 403 (?i)/tmp/.*\.php$
RedirectMatch 403 (?i)/modules/.*\.php$
RedirectMatch 403 (?i)/uploads/.*\.php$
RedirectMatch 403 (?i)/assets/.*\.php$
RedirectMatch 403 (?i)/assets/.*\.tpl$

---shorter version and faster-----------------------------
<FilesMatch "(?i)(?:config\.php|\.(?:htaccess|log|ini))$">
    Redirect 403 /
</FilesMatch>

RedirectMatch 403 /doc/
RedirectMatch 403 (?i)/(?:lib|tmp|modules|uploads)/.*\.php$
RedirectMatch 403 (?i)/assets/.*\.tpl$
-------------------------------


option 2 : improve performances (only one  backtracking)

root file /.htaccess
-------------------------------
<FilesMatch "(?i)(?:config\.php|\.(?:htaccess|log|ini))$">
    Redirect 403 /
</FilesMatch>

RedirectMatch 403 (?i)/tmp/.*\.php$
--------------------------------

folder doc/ CHMOD 700 or 750

/doc/.htaccess
----------------------------------------
<IfModule mod_authz_core.c>
    # Apache >= 2.4
    Require all denied
</IfModule>
<IfModule !mod_authz_core.c>
    # Apache <= 2.2
    Order Allow,Deny
</IfModule>
-----------------------------

.htaccess in folders /lib/ ,  /modules/ and /uploads/
NOTE : not in /tmp/ due to clear cache process from admin

/lib/.htaccess
/modules/.htaccess
/uploads/.htaccess
----------------------------------------
<FilesMatch "(?i)\.php$">
    Redirect 403 /
</FilesMatch>
-----------------------------


.htaccess in folders /assets/
assets/.htaccess
----------------------------------------
<FilesMatch "(?i)\.(?:php|tpl)$">
    Redirect 403 /
</FilesMatch>
-----------------------------


Note : security through obscurity return 404 instead 403

replace everywhere all 403 by 404
and
in /doc/.htaccess
replace all code by
Redirect 404 /

History